Flexible authorization access control method, related apparatus, and system
Abstract
This disclosure provides a flexible authorization access control method, a related apparatus, and a system. In the method, if an electronic device that receives an access request does not meet an authorization condition, is currently not suitable for authorization, or cannot currently obtain authorization from a user in time, the electronic device may select one electronic device in a distributed system as an authorization device. After obtaining a permission that is granted by the user and that is required for the access request, the authorization device notifies the electronic device, and then the electronic device may respond to the access request. In this disclosure, the electronic device can quickly and conveniently obtain the permission required for the access request and respond to the access request in a case in which the user is not disturbed, to ensure data security in the electronic device and meet a requirement of the user.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A flexible authorization access control method, applied to a first device, the method comprising:
obtaining, by the first device from a third device in a plurality of electronic devices, an access request that is used by an invoker in the third device to invoke an invokee in the first device to access a first resource in the first device, wherein the access request includes an identifier of the invoker in the third device, an identifier of the invokee and an identifier of the first resource, the first resource comprises a hardware resource that includes at least one of a camera, a fingerprint sensor, an audio device, a display, a motor, or a flash, and wherein the invoker is a first application (APP), the invokee is a second APP or a functional component, each of the first APP and the second APP is a program entity that implements a plurality of functions, and the functional component is a program entity that implements a single function; determining, by the first device, a second device in the plurality of electronic devices in one or more of the following cases: the first device is not configured with a first module configured to receive a first operation, the first device is configured with the first module and executes a first task by using the first module, the first device is in a screen-locked state, or a distance between the first device and a user is greater than a first value; sending, by the first device, an authorization request to the second device, wherein the authorization request is used to request the user to grant a first permission that comprises at least one of a permission to invoke the invokee in the first device, or a permission to access the first resource in the first device; receiving, by the first device, an authorization result sent by the second device, wherein the authorization result indicates that the user has granted the first permission; and invoking, by the first device, the invokee in response to the authorization result to access the first resource.
2 . The method according to claim 1 , wherein the first permission comprises at least one of:
a permission for the third device to invoke the invokee in the first device, or a permission for the third device to access the first resource in the first device.
3 . The method according to claim 1 , wherein before receiving, by the first device, the access request sent by the third device, the method further comprises:
sending, by the first device, first capability information to the third device, wherein the first capability information indicates that the first device opens a second permission to the third device, and the second permission comprises at least one of a permission to invoke the invokee in the first device or to access the first resource.
4 . The method according to claim 1 , wherein the first device and the second device log in to a same account.
5 . The method according to claim 1 , wherein the second device is a control device of the first device, the second device is a rich device, or the second device is an electronic device that keeps a communication connection to the first device for more than a preset duration.
6 . The method according to claim 1 , wherein the determining, by the first device, the second device in the plurality of electronic devices comprises:
determining, by the first device, the second device based on one or more of the following of the plurality of electronic devices: whether the first module is configured, a quantity of the configured first modules, a screen status, a running status, or distances between the plurality of electronic devices and the user.
7 . The method according to claim 6 , wherein
the second device is configured with the first module; and/or the second device meets one or more of the following: the screen status is an unlocked state, the running status indicates that the first task is not executed, or a distance between the second device and the user is less than a second value.
8 . The method according to claim 1 , wherein
the first operation comprises one or more of the following: a user operation performed on a display, a preset face image, a preset fingerprint, a preset voice instruction, or a user operation performed on a button.
9 . The method according to claim 1 , wherein the access request includes an identifier of the third device, and an identifier of the first device.
10 . The method according to claim 1 , wherein the first APP is an instant messaging application or an online classroom application.
11 . An electronic device, comprising:
one or more processors; and a memory coupled to the one or more processors and configured to store computer program code, wherein the computer program code comprises computer instructions that, when executed by the one or more processors, cause the electronic device to perform the following operations: obtaining an access request that is sent by a third device in a plurality of electronic devices and is used by an invoker in the third device to invoke an invokee in the electronic device to access a first resource in the electronic device; wherein the access request includes an identifier of the invoker in the third device, an identifier of the invokee and an identifier of the first resource, the first resource is a hardware resource that includes at least one of a camera, a fingerprint sensor, an audio device, a display, a motor, or a flash, and wherein the invoker is a first application (APP), the invokee is a second APP or a functional component, each of the first APP and second APP is a program entity that implements a plurality of functions, and the functional component is a program entity that implements a single function; determining a second device in the plurality of electronic devices in one or more of the following cases: the electronic device is not configured with a first module configured to receive a first operation, the electronic device is configured with the first module and executes a first task by using the first module, the electronic device is in a screen-locked state, or a distance between the electronic device and a user is greater than a first value; sending an authorization request to the second device, wherein the authorization request is used to request the user to grant a first permission, and the first permission comprises at least one of a permission to invoke the invokee in the electronic device, or a permission to access the first resource in the electronic device; receiving an authorization result sent by the second device, wherein the authorization result indicates that the user has granted the first permission; and invoking the invokee in response to the authorization result to access the first resource.
12 . The electronic device according to claim 11 , wherein the first permission comprises at least one of:
a permission for the third device to invoke the invokee in the electronic device, or a permission for the third device to access the first resource in the electronic device.
13 . The electronic device according to claim 11 , wherein the access request includes an identifier of the third device, and an identifier of the first device.
14 . The electronic device according to claim 11 , wherein the first APP is an instant messaging application or an online classroom application.
15 . A non-transitory computer-readable storage medium, comprising instructions that, when run on an electronic device, cause by the electronic device is enabled to perform:
obtaining an access request that is sent by a third device in a plurality of electronic devices and is used by an invoker in the third device to invoke the invokee in the first device to access a first resource in the first device, wherein the access request includes an identifier of the invoker in the third device, an identifier of the invokee and an identifier of the first resource, the first resource is a hardware resource that includes at least one of a camera, a fingerprint sensor, an audio device, a display, a motor, or a flash, and wherein the invoker is a first application (APP), the invokee is a second APP or a functional component, each of the first APP and second APP is a program entity that implements a plurality of functions, and the functional component is a program entity that implements a single function; determining a second device in the plurality of electronic devices in one or more of the following cases: the first device is not configured with a first module configured to receive a first operation, the first device is configured with the first module and executes a first task by using the first module, the first device is in a screen-locked state, or a distance between the first device and a user is greater than a first value; sending an authorization request to the second device, wherein the authorization request is used to request the user to grant a first permission, and the first permission comprises at least one of a permission to invoke the invokee in the first device, or a permission to access the first resource in the first device; receiving an authorization result sent by the second device, wherein the authorization result indicates that the user has granted the first permission; and invoking the invokee in response to the authorization result to access the first resource.
16 . The non-transitory computer-readable storage medium according to claim 15 , wherein the access request includes an identifier of the third device, and an identifier of the first device.
17 . The non-transitory computer-readable storage medium according to claim 15 , wherein the first APP is an instant messaging application or an online classroom application.Join the waitlist — get patent alerts
Track US12591654B2 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.